Junglewise Threat Intelligence

CVE-2026-20006: Cisco Secure Firewall Threat Defense TLS denial of service in Snort 3

CVE-2026-20006 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Technologies: Cisco Secure Firewall Threat Defense. Vendors: Cisco.

Executive brief

Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that inspects encrypted traffic to detect and block threats. A flaw in its TLS protocol handling within the Snort 3 detection engine allows a remote attacker to send a specially crafted TLS packet that crashes the detection engine, causing the firewall to drop all network traffic and resulting in service outage. The vulnerability only affects systems with Snort 3 enabled and specific SSL/decryption policies configured, and does not impact TLS 1.3 connections.

Technical details

This vulnerability is a denial of service flaw (CWE-388: Error in Exception Handling) in the TLS cryptography functionality of the Snort 3 Detection Engine within Cisco Secure FTD Software. The root cause is improper implementation of the TLS protocol that fails to properly validate or handle certain TLS packet structures. An unauthenticated remote attacker can exploit this by sending a crafted TLS packet to an affected device over the network (no authentication or user interaction required). A successful exploit causes the Snort 3 Detection Engine to unexpectedly restart, which results in a denial of service condition where network traffic is dropped. The vulnerability requires specific preconditions: Snort 3 must be enabled, an SSL/decryption policy must be deployed with a rule blocking specific TLS versions (1.0, 1.1, or 1.2), and the policy must be configured not to decrypt unsupported ciphers. Cisco has released software updates to address this issue, and workarounds are available.

Affected products

  • Cisco Secure Firewall Threat Defense Multiple versions with Snort 3 enabled

Timeline

  • 2026-03-04: disclosed

References

Related threats